查看: 2661|回复: 9
收起左侧

[病毒样本] Jetico Keygen

[复制链接]
悠柚
发表于 2008-2-11 14:28:58 | 显示全部楼层 |阅读模式
反病毒引擎;版本;最后更新;扫描结果
AhnLab-V3;2008.2.11.10;2008.02.11;-
AntiVir;7.6.0.62;2008.02.10;-
Authentium;4.93.8;2008.02.11;-
Avast;4.7.1098.0;2008.02.10;-
AVG;7.5.0.516;2008.02.10;-
BitDefender;7.2;2008.02.11;Packer.Krunchy.A
CAT-QuickHeal;None;2008.02.11;(Suspicious) - DNAScan
ClamAV;0.92;2008.02.10;-
DrWeb;4.44.0.09170;2008.02.10;-
eSafe;7.0.15.0;2008.01.28;Suspicious File
eTrust-Vet;31.3.5522;2008.02.08;-
Ewido;4.0;2008.02.10;-
FileAdvisor;1;2008.02.11;-
Fortinet;3.14.0.0;2008.02.11;-
F-Prot;4.4.2.54;2008.02.10;W32/Heuristic-162!Eldorado
F-Secure;6.70.13260.0;2008.02.10;Suspicious:W32/Malware!Gemini
Ikarus;T3.1.1.20;2008.02.11;Packer.Krunchy.A
Kaspersky;7.0.0.125;2008.02.11;-
McAfee;5226;2008.02.08;-
Microsoft;1.3204;2008.02.10;-
NOD32v2;2862;2008.02.10;-
Norman;5.80.02;2008.02.08;-
Panda;9.0.0.4;2008.02.10;Suspicious file
Prevx1;V2;2008.02.11;Generic.Malware
Rising;20.29.22.00;2008.01.30;-
Sophos;4.26.0;2008.02.11;Mal/EncPk-BP
Sunbelt;2.2.907.0;2008.02.09;-
Symantec;10;2008.02.11;-
TheHacker;6.2.9.216;2008.02.11;-
VBA32;3.12.6.0;2008.02.10;-
VirusBuster;4.3.26:9;2008.02.10;Packed/FRBR
Webwasher-Gateway;6.6.2;2008.02.11;Win32.Malware.gen (suspicious)

附加信息
File size: 102400 bytes
MD5: 4ddb6997d009ca79c377c6042b5437dd
SHA1: 51bafdc7c28ea48851b0cf08d03e728c66500c55
PEiD: kkrunchy 0.23 alpha -> Ryd
packers: Malware_Prot.J
Prevx info: http://info.prevx.com/aboutprogr ... 1295A9C6F008FCA16E5

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
悠柚
 楼主| 发表于 2008-2-11 14:30:58 | 显示全部楼层
KEYGEN.EXE
This executable program has a file size of 102,400 bytes, it is most frequently called KEYGEN.EXE and is most frequently located in the %mai%\ folder.
This file is considered unsafe. It was first seen on Friday, Sep 21 2007. It has been seen frequently by 5 users in this section of the community. The file has only been seen in SPAIN.
KEYGEN.EXE has been seen to perform the following behaviors:
- The Process is packed and/or encrypted using a software packing process
- This Process Creates Other Processes On Disk
KEYGEN.EXE has been the subject of the following behaviors:
- Created as a process on disk
- Executed as a Process
这是prevx对他的描述
gho
发表于 2008-2-11 14:34:15 | 显示全部楼层
mcafee pass
kkgh
发表于 2008-2-11 14:34:32 | 显示全部楼层
一个注册机
qigang
发表于 2008-2-11 14:42:04 | 显示全部楼层
注册机不一定要报毒!
juijui
发表于 2008-2-11 14:51:03 | 显示全部楼层
* Sandbox name: NO_MALWARE
    * Signature name: NO_VIRUS
    * Compressed: NO
    * TLS hooks: NO
    * Executable type: N/A
    * Executable file structure: OK
solcroft
发表于 2008-2-11 15:40:15 | 显示全部楼层
纯属报壳
Graybird
发表于 2008-2-11 17:23:36 | 显示全部楼层
The file 'Jeticokeygen.exe' has been determined to be 'DAMAGED FILE (UNKNOWN)'. In particular this means that this file is damaged and not working properly. We could not find any malicious content. However the heuristic detection module may still detect this particular file even though it is damaged. In that case we will not adjust and remove detection for this damaged file.
悠柚
 楼主| 发表于 2008-2-11 18:06:00 | 显示全部楼层
我发帖只是说明有许多软件在报壳而已
ykz1991
发表于 2008-2-11 20:11:25 | 显示全部楼层

回复 9楼 悠柚 的帖子

这个不用说明吧
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-28 00:29 , Processed in 0.133483 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表